GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The Senior Application Security Engineer will implement and improve application security tools, perform assessments, and advise clients on best practices.
Responsibilities:
- Implement, operationalize, and/or improve the configuration of client application security tools
- Perform manual application/API assessments of customer applications
- Assist customers with questions relating to practical use of application security tools
- Advise customers on application security best practices
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Requirements:
- Experiential understanding of the Software Development Lifecycle (SDLC)
- Experience with automation tools such as Jenkins
- Practical understanding of cloud infrastructure environments such as AWS/Azure/GCP including 'serverless' workflows
- In-depth knowledge of Application Security tools
- Fundamental knowledge of software composition analysis and code/library dependencies
- Experience with testing tools such as: Burp Suite, Netsparker, Veracode, Checkmarx, Snyk, Invicti, etc
- Deep understanding of a broad range of Application Security issues as well as their mitigation strategies
- Understanding of Application Security related vulnerabilities including cryptographic implementations
- Experience with reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#
- Written communication skills for written interactions with clients
- Strong communication skills that include the ability to clearly articulate thoughts and distill complex problems into stakeholder-friendly language
- Ability to manage time independently while handling multiple projects concurrently
- Standard industry certifications are preferred
- Significant knowledge of SAST, DAST, SCA, IAST, and/or RASP tooling preferred